GSA - Detect Connections Outside Operational Hours

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query identifies connections that occur outside of the defined operational hours. It helps in monitoring and flagging any unusual activity that may occur during non-business hours, indicating potential security concerns or policy violations.

Attribute Value
Type Analytic Rule
Solution Global Secure Access
ID 4c9f0a9e-44d7-4c9b-b7f0-f6a6e0d8f8fa
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1078, T1133
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
NetworkAccessTraffic ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Global Secure Access